vendor:
TestRail
by:
Sick Codes & JohnJHacking (Sakura Samuraii)
7.5
CVSS
HIGH
Improper Access Control
264
CWE
Product Name: TestRail
Affected Version From: Not specified
Affected Version To: 7.2.0.3014
Patch Exists: YES
Related CWE: CVE-2021-40875
CPE: a:gurock:testrail:7.2.0.3014
Tags: cve,cve2021,exposure,gurock,testrail
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Nuclei Metadata: {'max-request': 2, 'shodan-query': 'http.html:"TestRail"', 'vendor': 'gurock', 'product': 'testrail'}
Platforms Tested: macOS, Linux, Windows
2021
Gurock Testrail 7.2.0.3014 – ‘files.md5’ Improper Access Control
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application files and the corresponding file paths. The corresponding file paths can be tested, and in some cases, result in the disclosure of hardcoded credentials, API keys, or other sensitive data.
Mitigation:
Upgrade to Gurock TestRail version 7.2.0.3014 or above.